CVE-2013-1840: Infoleak
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1840?
CVE-2013-1840 has a severity rating that can allow remote authenticated users to expose sensitive backend credentials.
How do I fix CVE-2013-1840?
To fix CVE-2013-1840, upgrade to OpenStack Glance version 11.0.0a0 or later.
Which versions of OpenStack Glance are affected by CVE-2013-1840?
CVE-2013-1840 affects OpenStack Glance versions from Essex (2012.1) and Folsom (2012.2) up to but not including version 11.0.0a0.
Can the use of S3 storage expose me to CVE-2013-1840?
Yes, using the v1 API with S3 store in OpenStack can lead to risks associated with CVE-2013-1840.
Is CVE-2013-1840 relevant to both OpenStack Essex and Folsom?
Yes, CVE-2013-1840 is relevant to both OpenStack Essex (2012.1) and Folsom (2012.2) versions.